You are here: Re: [PHP] How can I secure database passwords used by PHP webpages « PHP « IT news, forums, messages
Re: [PHP] How can I secure database passwords used by PHP webpages

Posted by Dan Tappin on 03/02/05 17:31

The best way is to not store the password at all.

Store a hash of the password like this:

INSERT INTO users SET pass = MD5('password');

Now not knowing how you authenticate those passwords this might not
work.

If it's an internal web page via PHP all you do is MD5 the users
supplied password and compare to you DB.

Dan Tappin (The other Dan T)

On Mar 1, 2005, at 5:09 PM, Rob Tanner wrote:

> WE have a number of PHP webpages that access one of several MySql
> databases
> and while the PHP files that contain the passwords cannot be accessed
> via the
> web, we are becoming increasingly concerned over the possibility of
> other
> webpage maintainers viewing those files. How have other folks
> protected
> database passwords needed by PHP apps?
>
> Thanks.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация